About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



8 J. Cybersecurity 1 (2022)

handle is hein.journals/jnlocybrs8 and id is 1 raw text is: 





InM SAL OFT
    CYBER SEURT


Review article


Developing metrics to assess the effectiveness

of   cybersecurity awareness program

Sunil   Chaudhary *, Vasileios Gkioulos and Sokratis Katsikas

Department of Information Security and Communication Technology, Norwegian University of Science and
Technology, Teknologivegen 22, 2815 Gjovik, Norway

*Correspondence address. Department of Information Security and Communication Technology, Norwegian University
of Science and Technology, Ametyst-bygget 119, Teknologivegen 22, 2815 Gjovik, Norway. Tel: +47 93992516;
Email: sunil.chaudhary@ntnu.no
tsunil.chaudhary, vasileios.gkioulos, sokratis.katsikas@ntnu.no

Received 16 February 2021; revised 5 August 2021; accepted 12 April 2022


Abstract

Cybersecurity  awareness  (CSA) is not just about knowing, but also transforming things learned into
practice. It is a continuous process that needs to be adjusted in subsequent iterations to improve its
usability as well as sustainability. This is possible only if a CSA program is reviewed and evaluated
timely. Review  and evaluation of an awareness   program  offer an insight into the program's effec-
tiveness on the audience  and  organization, an invaluable piece of information  for the continuous
improvement of   the  program.  Further, it provides the information required  by the management
and sponsor  to decide on whether  to invest in the program or not. Despite these advantages, there
does  not exist a common  understanding  of what factors to measure  and how  to measure  them  dur-
ing the evaluation process.  As a result, we have proposed   evaluation metrics for the purpose.  In
order to do so, we performed   a literature review of 32 papers mainly to extract the following data:
(i) what factors did the paper measure,  and (ii) how did it measure the factors? Next, we adapted
the European  Literacy Policy Network's four indicators (i.e. impact, sustainability, accessibility, and
monitoring)  for awareness  evaluation  to make  it appropriate for evaluating a CSA  program.  We
believe that measuring  all four indicators will contribute to making the evaluation process system-
atic, complete, and replicable. More  importantly, it will help to produce more inclusive, accurate,
and  usable results for the future enhancement  of the program.

Key words: cybersecurity awareness, evaluation metrics, literature review, European Literacy Policy Network


Introduction
Cybersecurity is not just about technology, but it also includes the
people who interact with technology and are responsible for prop-
erly implementing and operating it. Many past studies [1-3] have
identified people's behaviors and actions to be responsible for most
cybersecurity incidents. This could be a reason why 'people' is con-
sidered the weakest link among the people-process-technology triad
of cybersecurity. As the first step in handling human factors, raising
the cybersecurity awareness (CSA) of people is of paramount impor-
tance.
   CSA combines both gains in knowledge and positive changes in
attitudes and behaviors (KAB) [4-7] that protect systems, data, and


information from cyber threats. The learning achieved from CSA ac-
tivities is not detailed or in-depth knowledge but only enough infor-
mation to direct the attention of individuals to security issues, per-
ceive their potential implications, and act responsibly (or make in-
formed decisions) [6, 8, 9]. This is done by communicating the needed
security information to the participants in a way so that they develop
a healthy level of skepticism and motivation to act when encoun-
tering unusual situations [10]. Practically, this encompasses different
dimensions, such as

•  Make  people realize that there are cyber risks and threats to
   which they are vulnerable.
•  Alert people about the harmful implications of cyber threats.


© The Author(s) 2022. Published by Oxford University Press. This is an Open Access article distributed under the terms of the Creative Commons Attribution License
(https://creativecommons.org/licenses/by/4.0/), which permits unrestricted reuse, distribution, and reproduction in any medium, provided the original work is properly cited.


  Journaof Cybersecurity, 2022,1-19
https://doi.org/10.1093/cybsec/tyac006
                  Review article